Improper Update of Reference Count Affecting unbound package, versions [,1.25.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.58% (45th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-UNBOUND-17660948
  • published28 Jun 2026
  • disclosed20 May 2026
  • creditUnknown

Introduced: 20 May 2026

CVE-2026-42534  (opens in a new tab)
CWE-911  (opens in a new tab)

How to fix?

Upgrade unbound to version 1.25.1 or higher.

Overview

Affected versions of this package are vulnerable to Improper Update of Reference Count in the jostle process. An attacker can cause degraded resolution performance and potentially disrupt DNS resolution by controlling a malicious DNS server that responds slowly or maliciously to queries, thereby exploiting retransmitted queries to prevent proper replacement of slow-running queries.

Workaround

This vulnerability can be mitigated by restricting network exposure, configuring the service to only accept queries from trusted internal networks, and forwarding queries exclusively to trusted, well-maintained upstream DNS servers. A service restart is required after configuration changes.

CVSS Base Scores

version 4.0
version 3.1